Malware · 10h ago

Firefox Add-on Hid Cookie Theft Until v1.4

Socket found a Firefox add-on, pdf-para-texto@extensao.local, that was published on September 3 and turned malicious in version 1.4 on September 11, when it began fetching a remote payload to steal Google session cookies and automate account takeover.

The extension shipped without hardcoded malicious code, URLs, or exfiltration endpoints. After installation, it pulled its instructions from attacker infrastructure and injected code into real accounts.google.com pages, letting it capture the victim’s Google session cookie and any password reset value Google asked for.

That means store review of the package alone can miss the real payload if the harmful behavior is only downloaded later. For teams that allow or review browser extensions, the exposure sits in active Google sessions, not just in the add-on code that was published.

Timeline

Sources

1 source covering this story

Part of the PlainSec briefing for 2026-09-24

Editions

Related stories